OpenClaw EnterpriseDOCSGitHub

ComputeDriver feature matrix

Compare the bundled Compute Drivers before choosing where to run Agents. The first table summarizes current Agent deployment paths. The detailed capability matrix is a reviewed source snapshot: it describes implementation components, not proof that a complete deployment or model request works. Its baseline and review date are shown above the generated table.

The local docs preview adds search, filters, and expandable source/test evidence to this page. On GitHub, status links in the table open pinned implementation sources. Full cell explanations and evidence are in the canonical matrix data.

Which Drivers can deploy an Agent?

Driver Current Agent deployment
Kubernetes Embedded OpenClaw supports an OCC Secret-backed API key. Dedicated Codex supports an OCC Secret-backed API key or a managed ChatGPT service-account credential.
SSH Supports embedded OpenClaw with harnessAuth.method: runtime; an operator must supply the model credential on the Linux host. No OCC-managed model credentials or dedicated Codex.
Docker/Podman Runs the local control plane, but rejects all current model-authentication bindings. A newly admitted Agent cannot be deployed through this Driver.

An optional OpenShell Sandbox Driver can be selected with Kubernetes, but stock OpenShell lacks required credential and workload-identity projection. It is not a supported Agent deployment path. The bundled Compute Drivers expose the current gateway authentication contracts:

Driver Gateway authentication
Kubernetes Trusted proxy only, with optional loopback password access.
Docker/Podman Managed password by default; explicit trusted proxy remains supported by the underlying container code. Current Agent admission limits still apply.
SSH Managed password by default; explicit trusted proxy remains supported.

Current Kubernetes storage uses a private Gateway RWO claim and a separate Harness-only RWO workspace. Replacements stop predecessors before starting the candidate. See the current storage contract.

The detailed matrix retains its older source baseline. Its shared-workspace/RWX and trusted-proxy rows are historical observations, not current storage or credential requirements. Use the current contracts above for those behaviors. For setup, see Drivers quickstart. The Compute Driver contract owns requirements; the platform architecture distinguishes implementation from remaining design work.

Read the matrix

A checkmark describes an individual implementation component. For example, Docker's embedded and dedicated topology code earns checkmarks in the pinned table, even though current Agent authentication prevents a new deployment. A required-contract row records an obligation; optional-capability rows record choices. Production also requires activation stages. Tests linked in the interactive view were not executed in this source review. No cell certifies a live model response or production readiness. Contributors can use the testing guide for runtime verification.

Bundled implementations

LocalTest is not a bundled selectable implementation in this snapshot. External ComputeDriver packages remain an extension point, not an additional implementation with inferred support. Selection and preflight rules belong to Driver selection.

Capabilities

ComputeDriver feature matrix

Reviewed 2026-09-16 at baseline 23d490b93d59dc810f28430f31576209200ba9ba.

Unknown means the available evidence does not establish support for that driver cell. Test links identify repository coverage only; they are not live-runtime proof.

32 rows

CapabilityRequirementDocker / PodmanKubernetesSSH
SelectionProduction startup selectionimplementation boundary
Requirement source

apps/controller/src/composition/installation-config.ts:647-690

Unsupported

Development-only Docker implementation; lacks production activation stages.

Source

docs/reference/drivers/docker-compute.md:9-12, apps/controller/src/drivers/compute/docker/index.ts:418-424

Live proof: unknown/not run

Supported

Bundled production Kubernetes selection; requires explicit cluster configuration.

Source

apps/controller/src/composition/installation-config.ts:663-690

Tests (not run)

tests/integration/ssh-compute-startup.test.mjs:84-95

Live proof: unknown/not run

Supported

Bundled compute-ssh selects occ/ssh in production; SSH is now on main.

Source

apps/controller/src/composition/installation-config.ts:654-662

Tests (not run)

tests/integration/ssh-compute-startup.test.mjs:43-59

Live proof: unknown/not run

LifecyclePrepare Namespace infrastructurerequired contract
Requirement source

packages/contracts/src/index.ts:688-689

Supported

Creates or verifies one owned bridge network per Namespace.

Source

apps/controller/src/drivers/compute/docker/index.ts:270-302

Live proof: unknown/not run

Supported

Creates or verifies tenant namespace, quotas, defaults and baseline network policy.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1035-1125

Live proof: unknown/not run

Supported

Creates or verifies marker on host selected by exact Namespace name.

Source

apps/controller/src/drivers/compute/ssh/index.ts:316-327, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:713-733

Live proof: unknown/not run

LifecycleDelete owned Namespace resourcesrequired contract
Requirement source

packages/contracts/src/index.ts:688-689

Supported

Verifies network ownership, removes owned containers and exact network.

Source

apps/controller/src/drivers/compute/docker/index.ts:305-321

Live proof: unknown/not run

Supported

Verifies ownership; retains externally managed namespace while removing owned infrastructure.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1128-1181

Live proof: unknown/not run

Supported

Stops owned units, removes owned Namespace tree and runtime identities.

Source

apps/controller/src/drivers/compute/ssh/index.ts:329-342, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:668-710

Tests (not run)

tests/conformance/ssh-compute.test.mjs:758-830

Live proof: unknown/not run

LifecyclePrepare immutable AgentRevisionrequired contract
Requirement source

packages/contracts/src/index.ts:690-693

Supported

Checks pinned driver, topology and configuration ownership before container preparation.

Source

apps/controller/src/drivers/compute/docker/index.ts:324-376

Live proof: unknown/not run

Supported

Prepares exact topology and owned resources with immutable configuration snapshots.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1184-1245, apps/controller/src/drivers/compute/kubernetes/index.ts:1383-1408

Live proof: unknown/not run

Supported

Writes immutable snapshot without changing current serving revision.

Source

apps/controller/src/drivers/compute/ssh/index.ts:345-377, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:562-625

Tests (not run)

tests/conformance/ssh-compute.test.mjs:758-830

Live proof: unknown/not run

LifecycleExplicit activation and deactivation stagesrequired in production

Optional methods in the shared interface; production startup rejects a selected ComputeDriver without both activation stages.

Requirement source

packages/contracts/src/index.ts:694-695, apps/controller/src/composition/installation-config.ts:683-690

Unsupported

No activation or deactivation methods; development prepare directly replaces gateway.

Source

apps/controller/src/drivers/compute/docker/index.ts:369-393, apps/controller/src/drivers/compute/docker/index.ts:483-494

Live proof: unknown/not run

Supported

Production stages verify exact workload readiness and update revision-aware Service routing.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1540-1558, apps/controller/src/drivers/compute/kubernetes/index.ts:1630-1661, apps/controller/src/drivers/compute/kubernetes/index.ts:1723-1759

Live proof: unknown/not run

Partial

Activation switches snapshot and restarts gateway; deactivation only verifies revision because dedicated topology is unsupported.

Source

apps/controller/src/drivers/compute/ssh/index.ts:380-406, apps/controller/src/drivers/compute/ssh/index.ts:421-424, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:626-665

Tests (not run)

tests/conformance/ssh-compute.test.mjs:847-868

Live proof: unknown/not run

LifecycleStop exact revision without retiring itrequired contract
Requirement source

packages/contracts/src/index.ts:694-697

Supported

Removes exact revision containers; leaves persisted revision outside Driver untouched; runtime tmpfs is lost.

Source

apps/controller/src/drivers/compute/docker/index.ts:418-455

Tests (not run)

tests/conformance/docker-compute.test.mjs:39-111

Live proof: unknown/not run

Supported

Stops routing and execution while retaining persistent claims.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1763-1796, apps/controller/src/drivers/compute/kubernetes/index.ts:1831-1891

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:3030-3156

Live proof: unknown/not run

Supported

Stops unit and removes current/served pointers while retaining snapshots and Agent state.

Source

apps/controller/src/drivers/compute/ssh/index.ts:426-430, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-771

Tests (not run)

tests/conformance/ssh-compute.test.mjs:486-575

Live proof: unknown/not run

LifecycleRetire predecessor without removing replacementrequired contract
Requirement source

packages/contracts/src/index.ts:696-697

Supported

Removes exact revision Agent container; removes gateway only if its revision ID still matches.

Source

apps/controller/src/drivers/compute/docker/index.ts:422-455

Live proof: unknown/not run

Supported

Retires owned workload and preserves replacement gateway and claims.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1798-1829, apps/controller/src/drivers/compute/kubernetes/index.ts:1959-1987

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:3370-3389

Live proof: unknown/not run

Supported

Retires only exact snapshot; stops unit only when retired revision is current.

Source

apps/controller/src/drivers/compute/ssh/index.ts:433-437, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-773

Tests (not run)

tests/conformance/ssh-compute.test.mjs:758-830

Live proof: unknown/not run

TopologyEmbedded OpenClaw Harnessimplementation boundary
Requirement source

docs/reference/drivers/compute.md:18-24

Supported

One combined gateway/Harness container.

Source

apps/controller/src/drivers/compute/docker/index.ts:369-376

Live proof: unknown/not run

Supported

Combined gateway/Harness Deployment, with Agent service identity.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1389-1405

Live proof: unknown/not run

Supported

Supported topology: systemd-managed OpenClaw gateway.

Source

apps/controller/src/drivers/compute/ssh/index.ts:351-355, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532

Live proof: unknown/not run

TopologyDedicated Codex Harnessimplementation boundary
Requirement source

docs/reference/drivers/compute.md:18-24

Partial

Separate gateway and exact-revision Codex container; transport retry limitation is listed separately.

Source

apps/controller/src/drivers/compute/docker/index.ts:379-393

Live proof: unknown/not run

Supported

Separate exact-revision Codex Deployment or selected Sandbox workload.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1477-1512

Live proof: unknown/not run

Unsupported

Explicitly rejects non-embedded OpenClaw; dedicated Codex deferred.

Source

apps/controller/src/drivers/compute/ssh/index.ts:351-355

Tests (not run)

tests/conformance/ssh-compute.test.mjs:670-719

Live proof: unknown/not run

LifecyclePreserve serving runtime until activationimplementation boundary
Requirement source

docs/reference/drivers/compute.md:65-83

Unsupported

Prepare removes prior gateway before creating replacement; no separate activation.

Source

apps/controller/src/drivers/compute/docker/index.ts:480-494

Live proof: unknown/not run

Supported

Preparation preserves predecessor; activation performs gateway replacement and routing cutover.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1383-1408, apps/controller/src/drivers/compute/kubernetes/index.ts:1540-1605

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:1321-1354

Live proof: unknown/not run

Supported

Prepare leaves current pointer and gateway untouched; activation switches and restarts.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:562-665

Tests (not run)

tests/conformance/ssh-compute.test.mjs:758-830

Live proof: unknown/not run

LifecycleZero-downtime gateway replacementimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute.md:154-161, docs/reference/drivers/ssh-compute.md:162-169

Unsupported

Replacement removes previous gateway first.

Source

apps/controller/src/drivers/compute/docker/index.ts:492-497

Live proof: unknown/not run

Unsupported

Gateway uses one replica and Recreate; transient downtime and node-fencing limits remain.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4184-4185, docs/reference/drivers/kubernetes-compute.md:156-161

Live proof: unknown/not run

Unsupported

Activation restarts existing systemd unit, interrupting service.

Source

docs/reference/drivers/ssh-compute.md:162-169, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:626-665

Live proof: unknown/not run

PlacementAdopt an existing tenant namespaceoptional capability
Requirement source

apps/controller/src/drivers/compute/kubernetes/index.ts:1041-1088

Unsupported

No Kubernetes existingNamespace adoption; own Docker network only.

Source

apps/controller/src/drivers/compute/docker/index.ts:270-298

Live proof: unknown/not run

Supported

Explicit adoption verifies active namespace, ownership uniqueness and existing network policy before claiming.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1041-1088

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:204-227, tests/integration/kubernetes-compute-real.test.mjs:1110-1123

Live proof: unknown/not run

Unsupported

Rejects existingNamespace input.

Source

apps/controller/src/drivers/compute/ssh/index.ts:440-443

Tests (not run)

tests/conformance/ssh-compute.test.mjs:670-719

Live proof: unknown/not run

CompositionDelegate dedicated Harness to SandboxDriveroptional capability
Requirement source

docs/reference/drivers/compute.md:46-63

Unsupported

No Sandbox composition in Docker development implementation.

Source

docs/reference/drivers/compute.md:46-49, apps/controller/src/drivers/compute/docker/index.ts:379-391

Live proof: unknown/not run

Supported

Delegates provisioning to selected SandboxDriver with exact identity and workload requirements; waits for exact ready Pod.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1496-1510

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:2005-2047, tests/conformance/kubernetes-compute.test.mjs:2211-2235

Live proof: unknown/not run

Unsupported

Explicitly rejects SandboxDriver selection.

Source

apps/controller/src/drivers/compute/ssh/index.ts:365-366

Tests (not run)

tests/conformance/ssh-compute.test.mjs:670-719

Live proof: unknown/not run

CompositionSelected-driver lifecycle hooksoptional capability
Requirement source

docs/reference/drivers/compute.md:114-131

Supported

Dispatches Namespace, start, stop and delete hooks; compensates failed preparation.

Source

apps/controller/src/drivers/compute/docker/index.ts:250-255, apps/controller/src/drivers/compute/docker/index.ts:297-297, apps/controller/src/drivers/compute/docker/index.ts:313-313, apps/controller/src/drivers/compute/docker/index.ts:366-414, apps/controller/src/drivers/compute/docker/index.ts:434-434

Live proof: unknown/not run

Supported

Dispatches hooks around owned Namespace/workload lifecycle.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1117-1120, apps/controller/src/drivers/compute/kubernetes/index.ts:1477-1478, apps/controller/src/drivers/compute/kubernetes/index.ts:1831-1865

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:1694-1722

Live proof: unknown/not run

Supported

Dispatches hooks around Namespace operations, activation and stop with failure compensation.

Source

apps/controller/src/drivers/compute/ssh/index.ts:316-335, apps/controller/src/drivers/compute/ssh/index.ts:403-417, apps/controller/src/drivers/compute/ssh/index.ts:426-437

Tests (not run)

tests/conformance/ssh-compute.test.mjs:627-668

Live proof: unknown/not run

CompositionInstall admitted native pluginsoptional capability
Requirement source

docs/reference/agent-plugins.md:1-20

Supported

Passes admitted plugin runtime to owning gateway or dedicated Agent.

Source

apps/controller/src/drivers/compute/docker/index.ts:359-390, apps/controller/src/drivers/compute/docker/index.ts:688-727

Tests (not run)

tests/conformance/plugin-compute.test.mjs:431-447

Live proof: unknown/not run

Supported

Projects plugin runtime and gates native readiness; configures required egress.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1479-1494, apps/controller/src/drivers/compute/kubernetes/index.ts:3950-3985

Tests (not run)

tests/conformance/plugin-compute.test.mjs:1008-1051

Live proof: unknown/not run

Unsupported

Rejects revisions whose admitted plugin map is nonempty; an empty map does not trigger this check.

Source

apps/controller/src/drivers/compute/ssh/index.ts:130-132, apps/controller/src/drivers/compute/ssh/index.ts:367-369

Live proof: unknown/not run

IsolationTenant network isolationimplementation boundary
Requirement source

docs/reference/drivers/docker-compute.md:77-79, docs/reference/drivers/kubernetes-compute.md:18-25, docs/reference/drivers/ssh-compute.md:209-213

Partial

Separate Namespace bridges; no per-workload default-deny ingress/egress policy.

Source

apps/controller/src/drivers/compute/docker/index.ts:270-298, apps/controller/src/drivers/compute/docker/index.ts:611-634

Live proof: unknown/not run

Supported

Default-deny ingress/egress plus explicit DNS and approved gateway ingress rules; requires enforcing cluster.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:3154-3178, docs/reference/drivers/kubernetes-compute.md:18-20

Live proof: unknown/not run

Unsupported

Separate Unix accounts, but shared host networking; operator owns network isolation.

Source

docs/reference/drivers/ssh-compute.md:209-213

Live proof: unknown/not run

IsolationExplicit CPU/memory limits and tenant quotasimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute.md:23-25

Unsupported

Container create sets bounded tmpfs, but no CPU/memory resource limits or tenant quota.

Source

apps/controller/src/drivers/compute/docker/index.ts:611-634

Live proof: unknown/not run

Supported

Namespace ResourceQuota and LimitRange; explicit role-specific Pod resources.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1090-1113, apps/controller/src/drivers/compute/kubernetes/index.ts:4235-4238

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:1610-1641

Live proof: unknown/not run

Unsupported

systemd unit has no CPU/memory quota directives.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532

Live proof: unknown/not run

IsolationNon-root workload executionimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute.md:18-20, docs/reference/drivers/ssh-compute.md:113-119

Supported

Containers run as UID/GID 1000.

Source

apps/controller/src/drivers/compute/docker/index.ts:595-598

Live proof: unknown/not run

Supported

Pod security context requires non-root UID/GID 1000.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4199-4208

Live proof: unknown/not run

Supported

Per-Agent non-login Unix account; SSH control connection itself requires root.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:313-366, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-516, apps/controller/src/drivers/compute/ssh/index.ts:237-240

Tests (not run)

tests/conformance/ssh-compute.test.mjs:758-830

Live proof: unknown/not run

IsolationWorkload filesystem and privilege restrictionsimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute.md:18-20

Supported

Read-only rootfs, dropped capabilities, no-new-privileges and bounded writable tmpfs.

Source

apps/controller/src/drivers/compute/docker/index.ts:611-624

Live proof: unknown/not run

Supported

Restricted Pod context, read-only rootfs, no escalation and dropped capabilities; bounded emptyDir.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4031-4038, apps/controller/src/drivers/compute/kubernetes/index.ts:4239-4243

Live proof: unknown/not run

Partial

Private Unix account, NoNewPrivileges and PrivateTmp; no container-equivalent read-only rootfs.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532

Live proof: unknown/not run

IdentityProject service-principal workload tokenimplementation boundary
Requirement source

docs/reference/drivers/compute.md:60-63

Unsupported

Service-principal labels, but no projected workload token.

Source

apps/controller/src/drivers/compute/docker/index.ts:595-634

Live proof: unknown/not run

Supported

Projects bounded audience-scoped ServiceAccount token read-only; disables ambient automount.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:3988-4007, apps/controller/src/drivers/compute/kubernetes/index.ts:4199-4200

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:1980-2003

Live proof: unknown/not run

Unsupported

Binds ServicePrincipal in ownership markers; no workload token projection.

Source

apps/controller/src/drivers/compute/ssh/index.ts:297-313, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:167-173

Live proof: unknown/not run

ConnectivityResolve private WSS gateway endpointoptional capability
Requirement source

packages/contracts/src/index.ts:687-687

Unsupported

Optional resolver absent.

Source

docs/reference/drivers/compute.md:94-97

Live proof: unknown/not run

Supported

Returns deterministic WSS address only when gateway routing is configured.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:861-865, apps/controller/src/drivers/compute/kubernetes/index.ts:3224-3236

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:411-436

Live proof: unknown/not run

Unsupported

Optional resolver absent; workspace-file API endpoint resolution unsupported.

Source

docs/reference/drivers/compute.md:94-97, docs/reference/drivers/ssh-compute.md:215-218

Live proof: unknown/not run

StoragePersist Agent state across runtime replacementimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:6-18, docs/reference/drivers/ssh-compute.md:177-186

Unsupported

Writable state is ephemeral tmpfs; no persistent workspace contract.

Source

apps/controller/src/drivers/compute/docker/index.ts:616-624, docs/reference/drivers/docker-compute.md:112-116

Live proof: unknown/not run

Supported

Private gateway RWO disk; embedded default workspace persists; dedicated RWX workspace is separate.

Source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:33-60, apps/controller/src/drivers/compute/kubernetes/index.ts:4041-4062

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:2791-2818

Live proof: unknown/not run

Supported

Private home/state directories persist across stop and revision retirement.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:562-625, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-771

Tests (not run)

tests/conformance/ssh-compute.test.mjs:486-575

Live proof: unknown/not run

StorageShare dedicated gateway/Harness workspaceimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:56-60

Unsupported

Separate ephemeral runtime homes; no shared volume mounts.

Source

apps/controller/src/drivers/compute/docker/index.ts:611-634

Live proof: unknown/not run

Supported

Shared Agent-owned 40Gi RWX claim with directional mount permissions.

Source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:56-60, apps/controller/src/drivers/compute/kubernetes/index.ts:4041-4047

Live proof: unknown/not run

Unsupported

Dedicated topology unsupported.

Source

apps/controller/src/drivers/compute/ssh/index.ts:351-355

Live proof: unknown/not run

CredentialsProvision initial Agent runtime credentialsoptional capability
Requirement source

packages/contracts/src/index.ts:680-686

Unsupported

No provisioning API; model credential supplied to development worker environment.

Source

apps/controller/src/drivers/compute/docker/index.ts:368-384, docs/reference/drivers/compute.md:151-160

Live proof: unknown/not run

Supported

Creates missing owned Secret groups; rejects conflicts and preserves matching existing values.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:867-953

Tests (not run)

tests/conformance/kubernetes-runtime-credentials.test.mjs:171-240

Live proof: unknown/not run

Unsupported

Operator-owned Agent env file is the credential path; no runtime-credential API.

Source

docs/reference/drivers/ssh-compute.md:195-207

Live proof: unknown/not run

CredentialsDeliver model credential only to executing Harnessimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:95-105, docs/reference/drivers/docker-compute.md:125-130

Supported

Provider key reaches embedded gateway or dedicated Agent; dedicated gateway gets only transport.

Source

apps/controller/src/drivers/compute/docker/index.ts:368-390

Live proof: unknown/not run

Supported

Agent harnessAuth selects an OCC Secret API key or account-owned token; only the model-executing workload receives it.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4076-4091, apps/controller/src/drivers/compute/kubernetes/index.ts:4121-4138

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:782-837, tests/conformance/kubernetes-compute.test.mjs:948-977

Live proof: unknown/not run

Partial

Operator env supplies embedded workload credentials; no Driver-managed model credential path.

Source

docs/reference/drivers/ssh-compute.md:203-207, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:521-521

Live proof: unknown/not run

CredentialsProject OCC Secret bindingsoptional capability
Requirement source

packages/contracts/src/index.ts:690-693, apps/controller/src/drivers/compute/kubernetes/index.ts:3814-3839

Unsupported

prepareRevision does not consume ComputeRevisionContext or project OCC Secret bindings.

Source

apps/controller/src/drivers/compute/docker/index.ts:324-324, apps/controller/src/drivers/compute/docker/index.ts:368-390

Live proof: unknown/not run

Partial

Custom bindings are projected into gateway only; dedicated Codex receives an empty projection list. Built-in model/transport credentials use separate supported paths.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:1389-1405, apps/controller/src/drivers/compute/kubernetes/index.ts:1479-1494, apps/controller/src/drivers/compute/kubernetes/index.ts:4018-4027

Live proof: unknown/not run

Unsupported

Explicitly rejects OCC Secret bindings; operator env file is separate.

Source

apps/controller/src/drivers/compute/ssh/index.ts:357-363

Tests (not run)

tests/conformance/ssh-compute.test.mjs:670-719

Live proof: unknown/not run

CredentialsBackend-issued dedicated Codex access tokenoptional capability
Requirement source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:95-100

Unsupported

Only provider API-key environment supported in this implementation.

Source

apps/controller/src/drivers/compute/docker/index.ts:368-390, apps/controller/src/drivers/compute/docker/index.ts:677-686

Live proof: unknown/not run

Supported

Account-owned access-token Secret and workspace ID project only to dedicated Codex.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4121-4138

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:948-1032

Live proof: unknown/not run

Unsupported

Dedicated Codex unsupported.

Source

apps/controller/src/drivers/compute/ssh/index.ts:351-355

Live proof: unknown/not run

CredentialsPersist dedicated transport authentication across retriesimplementation boundary
Requirement source

docs/reference/drivers/compute.md:81-83

Partial

Source-inferred retry gap, unreproduced: a fresh token is generated each prepare, while a healthy existing Agent is reused; rebuilding only gateway can supply a different token.

Source

apps/controller/src/drivers/compute/docker/index.ts:379-390, apps/controller/src/drivers/compute/docker/index.ts:483-494, apps/controller/src/drivers/compute/docker/index.ts:549-564

Live proof: unknown/not run

Supported

Both roles reference the same persisted Agent-owned transport Secret; initial provisioning generates transport bytes only if that group is absent. This source evidence does not prove every runtime retry or external rotation scenario.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4064-4074, apps/controller/src/drivers/compute/kubernetes/index.ts:909-923

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:782-837

Live proof: unknown/not run

Unsupported

Dedicated transport unsupported.

Source

apps/controller/src/drivers/compute/ssh/index.ts:351-355

Live proof: unknown/not run

ConnectivityHonor native trusted-proxy gateway authenticationoptional capability
Requirement source

docs/reference/drivers/kubernetes-compute/storage-and-credentials.md:82-93

Supported

At the reviewed baseline, explicit trusted-proxy mode omitted the gateway credential. The current Driver supports password or trusted-proxy authentication only; see the current Driver reference.

Source

apps/controller/src/drivers/compute/docker/index.ts:508-511

Tests (not run)

tests/conformance/docker-compute.test.mjs:113-132

Live proof: unknown/not run

Supported

At the reviewed baseline, private routing verified explicit trusted-proxy settings. The current Driver always renders trusted-proxy authentication from Installation settings; see the current Driver reference.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:3240-3255, apps/controller/src/drivers/compute/kubernetes/index.ts:4093-4102

Tests (not run)

tests/conformance/kubernetes-runtime-credentials.test.mjs:318-344

Live proof: unknown/not run

Supported

At the reviewed baseline, the trusted-proxy unit omitted its generated gateway credential file. The current Driver supports password or trusted-proxy authentication only; see the current Driver reference.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-521, docs/reference/drivers/ssh-compute.md:197-201

Tests (not run)

tests/conformance/ssh-compute.test.mjs:576-625

Live proof: unknown/not run

OperationsSchedule periodic active-runtime maintenanceoptional capability
Requirement source

packages/contracts/src/index.ts:676-677

Unsupported

No maintenanceIntervalMs declaration; event-driven lifecycle.

Source

apps/controller/src/drivers/compute/docker/index.ts:231-238, docs/reference/drivers/compute.md:99-112

Live proof: unknown/not run

Unsupported

No maintenanceIntervalMs declaration; Kubernetes controller handles workload reconciliation separately.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:629-638, docs/reference/drivers/compute.md:99-112

Live proof: unknown/not run

Unsupported

No maintenanceIntervalMs declaration; systemd restart policy is distinct.

Source

apps/controller/src/drivers/compute/ssh/index.ts:253-261, docs/reference/drivers/ssh-compute.md:215-219

Live proof: unknown/not run

OperationsRuntime log collection pathimplementation boundary
Requirement source

docs/reference/drivers/docker-compute.md:37-39, docs/reference/drivers/ssh-compute.md:171-175

Partial

Optional Docker Fluentd forwarding; Podman logging overlay remains unverified/unsupported on documented baseline.

Source

apps/controller/src/drivers/compute/docker/index.ts:626-628, apps/controller/src/drivers/compute/docker/index.ts:652-665, docs/reference/drivers/docker-compute.md:37-39

Live proof: unknown/not run

Supported

Labels workloads and supplies native admitted logging levels for collection.

Source

apps/controller/src/drivers/compute/kubernetes/index.ts:4012-4016, apps/controller/src/drivers/compute/kubernetes/index.ts:4184-4198

Live proof: unknown/not run

Supported

Native systemd stdout/stderr collected by journald.

Source

apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532, docs/reference/drivers/ssh-compute.md:171-175

Live proof: unknown/not run

OperationsEnforce immutable runtime image digestsimplementation boundary
Requirement source

docs/reference/drivers/kubernetes-compute.md:145-149

Unsupported

Accepts engine-resolved tags as well as digests for development.

Source

docs/reference/drivers/docker-compute.md:101-105, apps/controller/src/drivers/compute/docker/index.ts:240-247

Live proof: unknown/not run

Supported

Production requires immutable SHA-256 image references.

Source

docs/reference/drivers/kubernetes-compute.md:145-149

Tests (not run)

tests/conformance/kubernetes-compute.test.mjs:1952-1978

Live proof: unknown/not run

Unsupported

Host binary paths are operator-managed; no container image pinning.

Source

apps/controller/src/drivers/compute/ssh/index.ts:42-47, docs/reference/drivers/ssh-compute.md:218-219

Live proof: unknown/not run

Update this snapshot

Edit docs/assets/compute-driver-matrix.json after reviewing the intended source revision. Keep implementation citations and test citations separate. Regenerate this table with node scripts/generate-compute-matrix.mjs; the docs build rejects a stale fallback. Follow local preview validation and record executed proof separately from support judgments.

Search documentation